IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/43081 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/64890 | vdb entry |
http://www.vupen.com/english/advisories/2011/0223 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM25698 | vendor advisory |
http://www.kb.cert.org/vuls/id/375127 | third party advisory us government resource |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM24319 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM24320 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM26397 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM25191 | vendor advisory |
http://osvdb.org/70688 | vdb entry |
http://www.ibm.com/support/docview.wss?uid=swg21460422 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM22167 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM22159 | vendor advisory |
http://www.securityfocus.com/bid/45989 | vdb entry |